Vulnerability  ·  2026-09-30

ClaraVerse agent tools SSRF-protection bypass reaches internal services and cloud metadata

VulnerabilityMedium impactGlobalCVE-2026-102879
NVD published CVE-2026-102879 (CVSS 5.0 v3.1) on 2026-09-29. ClaraVerse's download/scrape agent tools contain SSRF protection bypasses enabling internal/IMDS requests from the GenAI agent server (issue #254).
Agent tools with fetch/scrape capabilities are the classic SSRF surface in LLM application servers — the flaw lets an authenticated agent user reach internal services and cloud metadata (IMDS credentials) from the AI deployment host, though the package is niche.
Authenticated users invoke the download_file / scrape_web agent tools with URLs that bypass hostname validation and IPv6-transition-address filtering, making the server request internal services and cloud-instance metadata endpoints (SSRF, CWE-918).
ClaraVerse through 0.3.1 (download_file and scrape_web agent tools, backend/internal/security/ssrf.go)
Harden the SSRF validator (resolve DNS before allowlist checks, block IPv6 transition encodings and non-global ranges); upstream fix pending (issue #254).
NVD CVE-2026-102879ClaraVerse issue #254VulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →